Section 3 of SOC 2 Type 2 report — mandatory narrative describing infrastructure, software, people, procedures, and data per AICPA Description Criteria DC 200 (2018 revision).
A compliant Management's Description of the System for SOC 2 Type II must include the following17 sections. Each section addresses a specific control requirement that auditors will review.
Company history, mission, and service positioning.
Services in scope, products covered, and the Trust Services Criteria selected (Security / Availability / Confidentiality / Processing Integrity / Privacy).
Commitments made to customers and the system requirements that support them.
Cloud regions, data centers, network architecture, hardware boundaries.
Operating systems, databases, application stack, and supporting tools (monitoring, logging, IDS, SIEM).
Organizational structure, functional teams, headcount by role, and reporting lines.
Summary of documented procedures — onboarding, access management, change management, incident response, access reviews.
Data types, classification scheme, data flows (ingress/egress), retention, and protection at rest/in transit.
What is included vs excluded from the system description.
Third-party providers in scope (AWS, Okta, etc.), carve-out vs inclusive method, and the complementary controls expected at each subservice.
Tone at the top, ethics, board oversight, competence commitment (CC1.1–CC1.5).
How the organization identifies, analyzes, and responds to risk (CC3.1–CC3.4).
Internal and external communication channels for security matters (CC2.1–CC2.3).
Ongoing and separate evaluations of controls (CC4.1–CC4.2).
Controls the customer must implement for the service commitments to be achieved.
Material changes to the system during the observation period.
System incidents during the observation period disclosed per SSAE 21 (or explicitly "None identified").
This template shows the required structure. PoliWriter generates a fully customized Management's Description of the System that references your actual cloud providers, identity systems, tools, and team practices — ready for auditor review.
Establishes the overarching information security program and governance structure.
Defines requirements for managing user access based on least privilege.
Establishes password creation, management, and rotation requirements.
Defines data classification levels and handling requirements.
Defines acceptable and prohibited uses of company systems and data.
Structured approach for detecting, responding to, and recovering from security incidents.
Ensures critical business functions continue during and after disruptions.
Procedures for recovering IT infrastructure after catastrophic events.